Daily Beirut

Tech & Science

DragonDoll Spyware Targets Android Users Across 26 Countries

Security experts warn Android users in over 26 countries, including Russia, of the DragonDoll spyware, which grants attackers near-total device control and steals messaging app data.

··1 min read
DragonDoll Spyware Targets Android Users Across 26 Countries
Share

Security researchers have issued a global alert regarding a newly identified Android spyware application named DragonDoll, urging users to exercise immediate caution.

Geographic scope and attribution

The threat has been detected among Android users in more than 26 countries, including Russia, according to Russian news agency Novosti, citing findings from cybersecurity firm Positive Technologies.

Capabilities and operational mechanics

In a formal statement, Positive Technologies confirmed that DragonDoll provides attackers with near-complete control over infected devices. The malware exfiltrates sensitive user data, specifically including private conversations from instant messaging applications.

Infection occurs via a counterfeit website impersonating the official Google Chrome browser page. Victims are prompted to “update” their browser, which instead triggers the installation of the malicious software onto their device.

Post-infection functionality

Once installed, DragonDoll enables attackers to remotely manipulate the compromised device. Functions include turning the screen on or off, logging keystrokes, capturing screenshots, reading text messages, and intercepting passwords and PINs through spoofed interface windows.

The spyware also accesses chat histories and contact lists within Telegram, WhatsApp, and Viber. It further intercepts the content of system notifications as they appear. All collected data is encrypted before transmission to servers controlled by cybercriminals.

Russia’s Ministry of Internal Affairs had previously warned, in June, about another malicious program—Drama RAT—being deployed against Android devices. That malware is distributed via messaging apps, SMS, and email, often disguised as free access to ChatGPT, Yandex.Music, or a new VPN service. Criminals also attach it to files labeled “tax declaration” or “payment invoice.”

Add Daily Beirut to your Google News feed to get the latest first.
Share